Quote Originally Posted by ftpjesus View Post
Quote Originally Posted by KBriggs View Post

FYI, I did release an update (6.15) yesterday that will stop the simple resource edit that was discussed above where the javascript client gets patched. That code is compiled directly into the server's executable. Of course it doesn't do anything about previous versions and a site operator with evil intentions is likely not going to upgrade his copy. And it's not going to stop more sophisticated hacks that could modify the machine code and blank out the code integrity check.
Based on the interview I don't think you have much to worry about Kent it seemed based on what I heard that it would require the hack to be patched as well Im guessing probably everytime PM is updated which would be an onerous process probably.. Again I think if a site keeps its software updated it should instill a sense of trust especially since the hacker even said PM is more secure then some other bigger names out there..
Despite the fact its been patched rumor has it some scammers are still trying to sell this exploit either knowing it wont work anymore or are ignorant of that fact..